-----BEGIN PGP SIGNED MESSAGE----- Hash: SHA512 Format: 1.8 Date: Sun, 12 Jul 2026 10:54:58 +0200 Source: imagemagick Architecture: source Version: 8:6.9.11.60+dfsg-1.3+deb11u15 Distribution: bullseye-security Urgency: high Maintainer: ImageMagick Packaging Team <pkg-gmagick-im-team@lists.alioth.debian.org> Changed-By: Bastien Roucariès <rouca@debian.org> Changes: imagemagick (8:6.9.11.60+dfsg-1.3+deb11u15) bullseye-security; urgency=high . * Backport policy from 6.9.13-58 * Fix CVE-2026-53466: An integer overflow in the XCF decoder can result in an out of bounds read when a crafted image is read, potentially resulting in a crash. * Fix CVE-2026-53467: The MNG decoder contains a possible heap information disclosure vulnerability because part of the pixels are left unchanged. * Backport draw.c from 6.9.13-52 * Fix CVE-2026-55577: A heap buffer overflow occurs in the MVG decoder that could result in an out of bounds write when processing a crafted image. * Fix CVE-2026-55594: A missing depth check in the MVG decoder will result in a stack overflow when a crafted image is provided * Fix CVE-2026-55595 When providing invalid arguments to the connected-components option an infinite loop will occur. * Fix CVE-2026-55597: An incorrect handling of arguments can cause a heap buffer over-write in the JP2 encoder * Fix CVE-2026-55628: The `-concatenate` operation is missing policy checks, potentially resulting in both reading and writing to paths disallowed by the security policy * Fix CVE-2026-56361: Attackers can trigger heap buffer overflow by providing incorrect morphology parameters causing single pixel memory access violations. * Fix CVE-2026-56363: A division by zero vulnerability in binomial kernel processing that allows attackers to cause denial of service. * Fix CVE-2026-56365: A memory leak vulnerability in the PNG encoder when writing MNG images. Attackers can trigger the encoder failure condition to exhaust memory resources and cause denial of service. * Fix CVE-2026-56366: A memory leak vulnerability in the META reader when processing APP1JPEG input paths. Attackers can trigger this memory leak by providing specially crafted APP1JPEG image files, causing denial of service through resource exhaustion. * Fix CVE-2026-56367: An integer overflow in the PSB (PSD v2) RLE decoding path (ReadPSDChannelRLE in coders/psd.c) that causes a heap out-of-bounds read on 32-bit builds. * Fix CVE-2026-56368: A memory leak vulnerability in multiple coders that write raw pixel data where allocated objects are not properly freed. Attackers can trigger this leak by processing specially crafted images, causing memory exhaustion and denial of service. * Fix CVE-2026-56370 An out-of-bounds access vulnerability in ConnectedComponentsImage() when processing connected-components artifacts with invalid indices. * Fix CVE-2026-56371 a memory leak in coders/txt.c when processing TXT files with texture attributes: the texture object allocated via ReadImage is not released when GetTypeMetrics fails, leaking memory each time a crafted TXT file with a texture attribute is processed. * Fix CVE-2026-56373: A use-after-free vulnerability in the PDB decoder that uses a stale pointer when memory allocation fails. Attackers can trigger this vulnerability by processing malicious PDB files to cause crashes or write a single zero byte to freed memory. * Fix CVE-2026-56376: A heap use-after-free in the meta coder: when memory allocation fails, a single byte is written to a stale pointer. * Fix CVE-2026-56377: An incorrect policy check that allows attackers to create or truncate files disallowed by security policies. Remote attackers can bypass path policy restrictions in sandboxed conversion services to write arbitrary files outside intended boundaries. * Fix CVE-2026-56378: A heap out-of-bounds read in the PCD coder's DecodeImage loop. A crafted PCD file can trigger a one-byte heap out-of-bounds read during image decoding, resulting in denial of service and potential disclosure of an adjacent heap byte. Checksums-Sha1: 00ade7cdf27eeafaeafa5119ba4fd02aca707742 5232 imagemagick_6.9.11.60+dfsg-1.3+deb11u15.dsc 824a63dce5e54bd8b78077d671d8ab06300a8848 9395144 imagemagick_6.9.11.60+dfsg.orig.tar.xz 7b3fae3e07ac65f4339b2439d77726d8a703312d 365000 imagemagick_6.9.11.60+dfsg-1.3+deb11u15.debian.tar.xz 1688404d91bcaab80bbd454780cf1f454434f04d 9057 imagemagick_6.9.11.60+dfsg-1.3+deb11u15_source.buildinfo Checksums-Sha256: 2d0e5dbc44b3e26ebb6768e9bb7356c0a348f704c8128bc7a7a670304f28b82b 5232 imagemagick_6.9.11.60+dfsg-1.3+deb11u15.dsc 472fb516df842ee9c819ed80099c188463b9e961303511c36ae24d0eaa8959c4 9395144 imagemagick_6.9.11.60+dfsg.orig.tar.xz 7a4bfbc7245116fd6a4dd53d3778fd0b8d10d9e2738779bf8ca8efc32081c3d0 365000 imagemagick_6.9.11.60+dfsg-1.3+deb11u15.debian.tar.xz 0e63c76014b59825c50a3333dcc48ee6f23c6f4d6a8c800574e983814ce67424 9057 imagemagick_6.9.11.60+dfsg-1.3+deb11u15_source.buildinfo Files: 39d10fc518beba60d60d26495212b5f1 5232 graphics optional imagemagick_6.9.11.60+dfsg-1.3+deb11u15.dsc 8b8f7b82bd1299cf30aa3c488c46a3cd 9395144 graphics optional imagemagick_6.9.11.60+dfsg.orig.tar.xz 11b5475d53fdcd969b4c16f4e00ed5e5 365000 graphics optional imagemagick_6.9.11.60+dfsg-1.3+deb11u15.debian.tar.xz 68152e992a55fbf98168404935909699 9057 graphics optional imagemagick_6.9.11.60+dfsg-1.3+deb11u15_source.buildinfo -----BEGIN PGP SIGNATURE----- wsG7BAEBCgBvBYJqU9ZECRAAOhotqkEIX0cUAAAAAAAeACBzYWx0QG5vdGF0aW9u cy5zZXF1b2lhLXBncC5vcmezDUpedXrKnAVAKp/Do1qUMbDFpPDo4R33si6/K7xt 7RYhBF0Bh7lAokW617D1agA6Gi2qQQhfAACGzg//SAXvjNuzL1X2UlEzp5uQikMl eW5Z9oAtxcwbCL9JVtNzHINjGz1fUakT9jM8O3gaj/nXSdzStG/q+ck7A4YGTCJT ojEFcf/nEElsa4Q3/o5Ej6oifjlav2Wrc7scJ1Iw2/hlxyeC6FLOBY4lZl1E5s4W zfuebVwR2mpMEkGtJQtSogRubX/JEv4N3AzNGOdla+ORR7avr4C/POV2WaPhM+dL WeZ/CMjkXbvupafR8b506sDCm3O6jQaKKwIgqOU/BXMTPS++/PWYICOitJ4MI5J5 yxSVeBF3xQ5oR2tGPD32u50eM2ZFQdf9Ke8OSEtREig8sUYZfo5JAC1w2lxcEnja GWBZMd+QrsDX4AWUmLdLnlXsuS0IWu8tR2llrn9HvOuKiLoL5gZcdYdpuq13V1bk mM7BD4S/MKXoN9MLGpfb/BcMvzrv6XNLwqemMGIOOWp5f/Xp16FmwhZiohZqYVqh BOpvWmBNy8hNUGZbHIyS4qvY1RDacJtOgrHP+WHitZ+Yg0qRO4uRlJVaa2GrIvww 2iTF2QlEED8QlwSYOOt/6qtf1Vp/GzYpzw0ozp6tpX8LuKW1kS2jRLZA4U6CEAN+ eOHvxhsTC7HEcQb9sN3LqOCv4vEx3uXxo572XrkrGMEKedu5/ega326F+2gw6cM3 4STo9Guh6V7gF7TjoXU= =QdpT -----END PGP SIGNATURE-----